Cross-site Scripting
Jenkins Brakeman Plugin does not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site scripting vulnerability exploitable by users able to control the Brakeman post-build step input data.